Identity is the new perimeter. Most organisations are still defending the old one.
Email runs on identity. Files run on identity. Cloud apps run on identity. Admin portals, remote sessions and line-of-business systems now sit behind it. When that layer is loose, every other control has to compensate. When it is well designed, the rest of the stack becomes easier to secure and operate.
The issue is not whether MFA is enabled. It is whether the identity layer is designed, monitored and operated properly — authentication strength by role, Conditional Access coverage, admin privilege, device trust, non-human identities, session protection and mailbox-side signals.
Three questions that explain why identity is now the front door
What “identity is the front door” means in practice, why MFA-on is not the same as identity-ready, and what an identity review actually examines.
What does “identity is the front door” actually mean?
The login is now where access decisions actually happen. Email, files, line-of-business apps, admin portals, remote sessions and most cloud workflows sit behind identity. When attackers want in, they target the identity layer, not the network edge. When defenders want to control access, the levers are in identity policy, not the firewall.
We have MFA on. Why isn't that enough?
Because MFA presence and identity readiness are different things. Push-based and SMS MFA are still phishable. Legacy authentication can bypass MFA entirely. Stolen tokens can let attackers replay valid sessions without re-authenticating. Per-user MFA leaves admins, executives and finance staff treated the same as everyone else. The MFA tickbox is the starting point; the identity posture determines what an attacker can actually reach.
What does an identity review actually examine?
Six areas: authentication methods by persona, Conditional Access coverage by resource and scenario, admin role design including standing privilege, device trust and session protection, non-human identity hygiene, and monitoring depth across all sign-in log types and mailbox forensics. The output is a current-state map and a prioritised list of work, not another slide deck.
The old perimeter was the network edge. It is no longer where access decisions are made.
- Firewall as the boundary
- Inside trusted, outside not
- Worked when apps in data centres, people at desks
- Decides on where the user is sitting
- The login is the security boundary
- Every access decision evaluated
- Signals user, device, location, application, risk
- Reach whatever the identity can reach
Microsoft Entra ID's Conditional Access engine evaluates user, device, location, application and risk for every access decision.
The MFA tickbox is comforting. The identity posture behind it is often not.
Most Australian SME and mid-market environments are not in the position of “we have no security.” They are in the position of “we have Microsoft 365, we turned MFA on, and we assumed identity was handled.” That assumption is the weak point — behind it sit familiar mechanisms that MFA-on-by-default does not solve.
The Australian data. 42% of Category 3 cyber incidents responded to by ASD's ACSC in FY2024-25 involved compromised accounts or credentials (Australian Signals Directorate, Annual Cyber Threat Report 2024-25). “We have MFA” is a true statement that often hides several gaps — the interesting question is what an attacker would actually have to do to walk through.
An identity review is a current-state map of how the identity layer actually operates today.
Not a Microsoft 365 audit and not a vendor sales motion. Scored against a defensible model, with a prioritised list of what to close first — output that supports both leadership decisions and technical remediation.
Authentication methods by persona
Standard users, admins, finance, executives and external paths each examined against actual authentication strength and allowed methods — not a single tenant-wide statement.
Conditional Access coverage and quality
Which policies cover which users, applications and admin roles, where report-only effects have been tested, where legacy authentication is still tolerated, and where gaps exist that nobody has yet noticed.
Privileged role design
Standing versus eligible access, count of Global Administrators, break-glass account configuration, access review cadence, and Privileged Identity Management posture if licensing allows.
Device trust and session protection
Compliant device enforcement, hybrid join state where relevant, device code flow restrictions, token protection scope, and critical event revocation behaviour.
Non-human identity hygiene
App registrations, service principals, user-based service accounts, certificate and secret inventory, federation opportunity, and direct Conditional Access applicability.
Monitoring and response depth
All sign-in log types in scope, audit log export, risky users and risky service principals reviewed, suspicious sending and forwarding patterns visible, and mailbox forensics readiness for the inevitable BEC investigation.
Each layer addresses something MFA presence alone does not.
A defensible identity posture is not a single product purchase. It is a set of design and operating choices that together raise the cost of compromise — each achievable for a mid-sized Australian organisation running Microsoft 365 with the right licence tier and the right operating discipline.
None of these are exotic. Most are achievable inside Microsoft 365 when licensing, configuration and operating ownership are aligned. The hard part is rarely the technology. It is treating identity like infrastructure rather than like an admin portal nobody visits.
Identity is now one of the core operating layers in modern IT.
The Inlight IT view is that identity controls access to email, files, cloud applications, admin portals, remote sessions and increasingly the systems that used to sit behind the network edge. When identity is loose, the rest of the security stack has to work harder. The gap is rarely that an organisation has done nothing — it is in the operating detail: which MFA methods are allowed, whether Conditional Access is enforced properly, how admin privilege is granted, whether service principals are reviewed, and whether mailbox and sign-in signals are monitored together. This is engineering work, not a tenant checklist.
Identity is now the perimeter. It deserves to be operated like one.
Treat identity as infrastructure
Design and enforce Conditional Access
Reduce standing admin privilege
Monitor sign-in and mailbox signals together
Where this is delivered.
A useful Microsoft 365 identity review should answer the practical question — who can access what, from where, on which device, with what authentication strength, under which policy, and how quickly would the team see and respond if that access was abused?
A scoped review that surfaces the current state across authentication strength, Conditional Access coverage, privileged role design, device trust, non-human identity hygiene and monitoring depth, and sequences remediation by exposure.
The configuration depth of the work — Conditional Access design, legacy authentication shutdown, phishing-resistant MFA on privileged accounts, application consent governance.
The deeper security operating layer above the managed IT baseline, keeping the identity layer from drifting back into default settings.
Identity is the front door. Find out where it is unlocked.
Review authentication, privileged access and sign-in controls across Microsoft 365.
Discuss your cyber security position